Sample viewer

vx.netlux.org/Virus.DOS.Whale.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:52:19.675574315Z 82 PC: 12b1d | Get DOS internal pointers (SYSVARS)
2018-12-17T21:52:19.678240246Z 97 PC: 12b58 | Reserved
2018-12-17T21:52:19.689590429Z 77 PC: 11fe0 | Get program return code
2018-12-17T21:52:19.694167297Z 72 PC: 12174 | Allocate memory
2018-12-17T21:52:19.700721616Z 72 PC: 1218d | Allocate memory
2018-12-17T21:52:19.706665955Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T21:52:19.711150859Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:52:19.715947859Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:52:19.720111021Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:19.7215773Z 62 PC: 122ab | Close file
2018-12-17T21:52:19.726390805Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:19.728229519Z 62 PC: 122ab | Close file
2018-12-17T21:52:19.733004193Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:19.735774425Z 62 PC: 122ab | Close file
2018-12-17T21:52:19.74024957Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:19.741661606Z 62 PC: 122ab | Close file
2018-12-17T21:52:19.746353712Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:19.747393761Z 62 PC: 122ab | Close file
2018-12-17T21:52:19.750109663Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:19.751305171Z 62 PC: 122ab | Close file
2018-12-17T21:52:19.754111248Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:19.755105111Z 62 PC: 122ab | Close file
2018-12-17T21:52:19.758853656Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:19.760197476Z 62 PC: 122ab | Close file
2018-12-17T21:52:19.762849136Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:19.763740737Z 62 PC: 122ab | Close file
2018-12-17T21:52:19.767416409Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:19.769450872Z 62 PC: 122ab | Close file
2018-12-17T21:52:19.772428143Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:19.774101682Z 62 PC: 122ab | Close file
2018-12-17T21:52:19.776719187Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:19.777642588Z 62 PC: 122ab | Close file
2018-12-17T21:52:19.780784001Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:19.781885Z 62 PC: 122ab | Close file
2018-12-17T21:52:19.784622394Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:19.786044299Z 62 PC: 122ab | Close file
2018-12-17T21:52:19.788865881Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:19.789884726Z 62 PC: 122ab | Close file
2018-12-17T21:52:19.793634221Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:19.795310187Z 54 PC: 9fa6e | Get free disk space
2018-12-17T21:52:19.82438518Z 67 PC: 9fa6e | Get or set file attributes
2018-12-17T21:52:19.832606719Z 67 PC: 9fa6e | Get or set file attributes
2018-12-17T21:52:20.170975567Z 61 PC: 9fa6e | Open file (Filename = 'C:\COMMAND.COM')
2018-12-17T21:52:20.175844174Z 50 PC: 9fa6e | Get disk parameter block for specified drive
2018-12-17T21:52:20.180194834Z 66 PC: 12372 | Move file pointer
2018-12-17T21:52:20.184577227Z 68 PC: 9fa6e | I/O control for devices (Set for = 'mfyW Wv WWj W WcW WW W5W')
2018-12-17T21:52:20.186299325Z 87 PC: 9fa6e | Get or set file date and time
2018-12-17T21:52:20.189698992Z 63 PC: 12383 | Read file or device (Read 44693 bytes on handle 5)
2018-12-17T21:52:20.205490165Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:20.20818457Z 87 PC: 9fa6e | Get or set file date and time
2018-12-17T21:52:20.21056515Z 66 PC: 9fa6e | Move file pointer
2018-12-17T21:52:20.212144501Z 63 PC: 9fa6e | Read file or device (Read 28 bytes on handle 5)
2018-12-17T21:52:20.217695496Z 66 PC: 9fa6e | Move file pointer
2018-12-17T21:52:20.219932546Z 63 PC: 9fa6e | Read file or device (Read 28 bytes on handle 5)
2018-12-17T21:52:20.222095889Z 66 PC: 9fa6e | Move file pointer
2018-12-17T21:52:20.22347901Z 42 PC: 9fa6e | Get date 0x9fa6e: ret
0x9fa6f: add bl, ch
0x9fa71: add dl, byte ptr [bx + si - 0x1800]
0x9fa75: push dx
0x9fa76: sahf
0x9fa77: xchg ax, bp
0x9fa78: scasw ax, word ptr es:[di]
0x9fa79: xchg ax, bp
0x9fa7a: push di
0x9fa7c: adc word ptr [bx + 0x11], dx
0x9fa7f: xchg ax, bp
0x9fa80: scasb al, byte ptr es:[di]
0x9fa81: add ax, 0x4500
0x9fa84: add byte ptr [bp + si + 0x10], bl
0x9fa88: jmp 0x9fa8b
0x9fa8a: stc
0x9fa8b: ret
0x9fa8c: add byte ptr [bx + si + 0x7046], bh
0x9fa90: add byte ptr [bx + di], al
0x9fa92: push ss
2018-12-17T21:52:20.225824715Z 62 PC: 9fa6e | Close file
2018-12-17T21:52:20.227512643Z 67 PC: 9fa6e | Get or set file attributes
2018-12-17T21:52:20.236947882Z 99 PC: 97ed7 | Get DBCS lead byte table pointer
2018-12-17T21:52:20.240911256Z 56 PC: 926f9 | Get or set country info
2018-12-17T21:52:20.244723053Z 64 PC: 98148 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T21:52:20.250696482Z 25 PC: 92762 | Get default drive
2018-12-17T21:52:20.254337425Z 71 PC: 949dd | Get current directory
2018-12-17T21:52:20.258929107Z 64 PC: 98148 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T21:52:20.263287854Z 2 PC: 949b2 | Character output (Char = '3e')
2018-12-17T21:52:20.266879886Z 93 PC: 92820 | File sharing functions
2018-12-17T21:52:20.27004714Z 93 PC: 92827 | File sharing functions
2018-12-17T21:52:20.273163763Z 10 PC: 92839 | Buffered keyboard input
2018-12-17T21:52:34.637498384Z 0 PC: 0 | Program terminate
2018-12-17T21:52:35.991576754Z 0 PC: 0 | Program terminate
2018-12-17T21:52:36.097235404Z 64 PC: 98148 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T21:52:36.104697748Z 41 PC: 928ae | Parse filename
2018-12-17T21:52:36.109267304Z 41 PC: 9292f | Parse filename
2018-12-17T21:52:36.112867009Z 41 PC: 9294c | Parse filename
2018-12-17T21:52:36.118499926Z 26 PC: 95df7 | Set disk transfer address
2018-12-17T21:52:36.123664786Z 71 PC: 95ff3 | Get current directory
2018-12-17T21:52:36.140758832Z 78 PC: 9fa6e | Find first file
2018-12-17T21:52:36.150529746Z 47 PC: 9fa6e | Get disk transfer address
2018-12-17T21:52:36.153381151Z 71 PC: 95e6c | Get current directory
2018-12-17T21:52:36.158200746Z 73 PC: 95509 | Release memory
2018-12-17T21:52:36.161309718Z 75 PC: 9dfa2 | Execute program
2018-12-17T21:52:36.169792719Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:36.172541011Z 54 PC: 9fa6e | Get free disk space
2018-12-17T21:52:36.182733946Z 67 PC: 9fa6e | Get or set file attributes
2018-12-17T21:52:36.188710274Z 67 PC: 9fa6e | Get or set file attributes
2018-12-17T21:52:36.205019661Z 61 PC: 9fa6e | Open file (Filename = 'A:\PRINT.COM')
2018-12-17T21:52:36.211795143Z 50 PC: 9fa6e | Get disk parameter block for specified drive
2018-12-17T21:52:36.222206112Z 87 PC: 9fa6e | Get or set file date and time
2018-12-17T21:52:36.224058976Z 66 PC: 9fa6e | Move file pointer
2018-12-17T21:52:36.225302814Z 63 PC: 9fa6e | Read file or device (Read 28 bytes on handle 5)
2018-12-17T21:52:36.22715531Z 66 PC: 9fa6e | Move file pointer
2018-12-17T21:52:36.228966725Z 63 PC: 9fa6e | Read file or device (Read 28 bytes on handle 5)
2018-12-17T21:52:36.230863474Z 66 PC: 9fa6e | Move file pointer
2018-12-17T21:52:36.232367218Z 42 PC: 9fa6e | Get date 0x9fa6e: ret
0x9fa6f: add bl, ch
0x9fa71: add dl, byte ptr [bx + si - 0x1800]
0x9fa75: add byte ptr [bx + di], al
0x9fa77: add byte ptr [bx + di], al
0x9fa79: add byte ptr [bp + di + 0x57], cl
0x9fa7c: adc word ptr [bx + 0x11], dx
0x9fa7f: push di
0x9fa80: adc word ptr [bx], cx
0x9fa82: add ax, 0x45
0x9fa85: lcall 0x1eb:0x10
0x9fa8a: stc
0x9fa8b: ret
0x9fa8c: add byte ptr [bx + si + 0x7046], bh
0x9fa90: xor ax, 0x1605
0x9fa93: add byte ptr [bp + si - 0x73f0], bl
0x9fa97: push es
0x9fa98: dec bp
0x9fa99: or al, byte ptr [bx]
0x9fa9b: mov dx, 0x1c13
2018-12-17T21:52:36.234789484Z 62 PC: 9fa6e | Close file
2018-12-17T21:52:36.236216631Z 67 PC: 9fa6e | Get or set file attributes
2018-12-17T21:52:36.24454085Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:36.247827521Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-17T21:52:36.251942485Z 76 PC: 12a4b | Terminate with return code (Return code = '36')
2018-12-17T21:52:36.255625058Z 77 PC: 11fe0 | Get program return code
2018-12-17T21:52:36.258741954Z 72 PC: 12174 | Allocate memory
2018-12-17T21:52:36.261892497Z 72 PC: 1218d | Allocate memory
2018-12-17T21:52:36.26737466Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T21:52:36.272093292Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:52:36.276238705Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:52:36.280254911Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:36.282071066Z 62 PC: 122ab | Close file
2018-12-17T21:52:36.286592656Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:36.288066882Z 62 PC: 122ab | Close file
2018-12-17T21:52:36.293008663Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:36.295465779Z 62 PC: 122ab | Close file
2018-12-17T21:52:36.300076638Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:36.301748785Z 62 PC: 122ab | Close file
2018-12-17T21:52:36.305717633Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:36.306993319Z 62 PC: 122ab | Close file
2018-12-17T21:52:36.311588409Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:36.313859332Z 62 PC: 122ab | Close file
2018-12-17T21:52:36.318843827Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:36.320264762Z 62 PC: 122ab | Close file
2018-12-17T21:52:36.325006939Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:36.326337416Z 62 PC: 122ab | Close file
2018-12-17T21:52:36.330499176Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:36.332683695Z 62 PC: 122ab | Close file
2018-12-17T21:52:36.337024657Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:36.338481325Z 62 PC: 122ab | Close file
2018-12-17T21:52:36.343252721Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:36.344574931Z 62 PC: 122ab | Close file
2018-12-17T21:52:36.348723665Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:36.350915787Z 62 PC: 122ab | Close file
2018-12-17T21:52:36.355871966Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:36.357287602Z 62 PC: 122ab | Close file
2018-12-17T21:52:36.362530825Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:36.364096938Z 62 PC: 122ab | Close file
2018-12-17T21:52:36.368448667Z 81 PC: 9fa6e | Get current PSP
2018-12-17T21:52:36.370683433Z 62 PC: 122ab | Close file
2018-12-17T21:52:36.389666779Z 99 PC: 97ed7 | Get DBCS lead byte table pointer
2018-12-17T21:52:36.394994784Z 56 PC: 926f9 | Get or set country info
2018-12-17T21:52:36.400829455Z 64 PC: 98148 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T21:52:36.408927347Z 25 PC: 92762 | Get default drive
2018-12-17T21:52:36.415760244Z 71 PC: 949dd | Get current directory
2018-12-17T21:52:36.423353509Z 64 PC: 98148 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T21:52:36.429747962Z 2 PC: 949b2 | Character output (Char = '3e')
2018-12-17T21:52:36.435120986Z 93 PC: 92820 | File sharing functions
2018-12-17T21:52:36.440900755Z 93 PC: 92827 | File sharing functions
2018-12-17T21:52:36.446946013Z 10 PC: 92839 | Buffered keyboard input